摘要
为有效地对Web应用威胁进行评估,分析了Web应用威胁现状,定义了Web应用威胁模型,提出了一种利用攻击图对Web应用进行威胁建模和定量评估的方法。描述了攻击图建模过程,并给出其生成算法。研究了利用攻击图对Web威胁进行量化评估的分析方法。通过一个典型的Web应用网络环境,对攻击图生成算法和Web威胁评估方法进行了验证。对Web应用进行量化威胁评估的结果,有效揭示了web应用面临的各种可能的威胁隐患和攻击路径,对有效抵御风险具有重要的意义。
A method of current web application threats was developed to quantitatively assess web application threats based on an attack graph.The attack graphic modeling is described for quantitative web application threat assessments.The attack graph generation algorithm and web threat assessment method were validated in a typical web application network environment.The threat assessment identifies every potential threat and attack route which are necessary for effective risk protection.
出处
《清华大学学报(自然科学版)》
EI
CAS
CSCD
北大核心
2009年第S2期2108-2112,共5页
Journal of Tsinghua University(Science and Technology)
关键词
WEB应用安全
威胁建模
攻击图
定量评估
web application security
threat modeling
attack graph
quantitative assessment